Spaghettifying DRAM
- MattSteelblade - 10604 sekunder sedanI cannot wait for the accompanying Black Hat talk. Christopher Domas is one of my absolute favorite all-time hackers. He does such a fantastic job of explaining his work. Some of my favorite talks of his:
- Psychological Warfare in Reverse Engineering https://www.youtube.com/watch?v=HlUe0TUHOIc
- The MoVfuscator https://www.youtube.com/watch?v=R7EEoWg6Ekk
- Hardware Backdoors in redacted x86 https://www.youtube.com/watch?v=jmTwlEh8L7g
- WhiteDawn - 4894 sekunder sedanThis is all great to get full unfettered access to your own system, as life should be.
I’m sure Xbox and PlayStation security groups are a little nervous right now though. Getting ring-0 on those machines is near impossible, but once you do then everything else becomes wide open
- weinzierl - 2459 sekunder sedanWhen I started with computers, DRAM was understandable by a teenager: RAS, CAS, read, done.
Ok, the necessary refresh was always a little pain, but still something manageable.
Nowadays, I feel you need three PhD's to even bring up a micro with DRAM and don't get me started on the proprietary binary blobs necessary just for DRAM access. No wonder PSRAM is a thing.
The corollary is that it shouldn't be too surprising that this gigantic attack surface provides many opportunities. (Of course that doesn't mean it is easy to find them, hat tip to Christopher Domas, just that I expect there to be many more).
- gmueckl - 6710 sekunder sedanOK, so this works on AMD Jaguar according to the README. That's a architecture from 2013. There's notes about Zen 3 having a different base address for the memory controller registers, but that's it. What newer CPUs does attack actually work on?
- raver1975 - 1897 sekunder sedanI spaghettify my memory every time I write C code.
- dzdt - 10446 sekunder sedanSo on an affected system, ring 0 root has access to pretty much everything that was hidden in negative ring territory. The page is pretty quiet about what other processor families might be similar beyond this specific AMD16h (an older AMD low-power family)?
- zahlman - 3854 sekunder sedanThis is only applicable if you already have root (in order to get beyond that), right? It doesn't expose new risk of local privilege escalation?
- ecshafer - 2454 sekunder sedanThis is so cool. Outside of a cool demo, and maybe some black hat type stuff, this is surely dangerous, a bad idea, and shouldn't be done in prod. But pure hacker ethos at its heart.
- devttyeu - 9679 sekunder sedanThe big question is whether this can break out of KVM and whether it can be microrode patched / patched in any other way.
And whether it's really real in the first place.
- dooglius - 7118 sekunder sedanI don't understand the threat model being attacked here. If you had physical DRAM access you could do all of this anyway right? And I would assume that an unprivileged user would not have write access to the DRAM controller registers?
- ipdashc - 8307 sekunder sedanI really hate to be that guy, but man, as someone who was and is a big Christopher Domas fan (and is way dumber than him, I mean, this stuff is seriously over my head)... it's been really disappointing to see him LLM'ing all the READMEs recently. They used to be a joy to read through, but now the Claudeisms made it such a slog I could barely get through a few paragraphs. I'm glad he's using the new tools to get even more cool stuff done, but I wish he'd have gone for a human writeup at the end.
- fulafel - 10015 sekunder sedanFascinating. So what is the DCT swizzling functionality designed for in the hardware originally?
- anthk - 1600 sekunder sedanOn IntelME/AMD PSP:
https://jxself.org/titanic.shtml
He did it well. On "security", the author loves more to own his code/adata than anything. as did the PDP10/ITS hackers.
- - 7164 sekunder sedan
- aecsocket - 10559 sekunder sedanHoly shit, Christopher Domas is back. I remember watching his Defcon talks on x86 shenanigans[^1][^2] and being amazed at what he's been able to discover. Then he got whisked away by Intel and now drops this. I'm excited.
- mschuster91 - 10638 sekunder sedanThe researcher behind this is obviously highly knowledgeable in reverse engineering CPUs to the tune it reminds me of the dwarves digging in Moria...
But why on earth do they have to use AI to write their writeups?!
- quotemstr - 6809 sekunder sedanThis is the level of access the rightful owner of a computer should have to his own system.
He should also be able to fuse away this access forever, to be fair. But out of the box, when I get a new laptop, I should be able to read and write every byte of DRAM.
- pocksuppet - 2751 sekunder sedanThis is probably very interesting, but does it really have to be explained with a solid wall of AI slop writing?
- UltraSane - 9590 sekunder sedanOpus refuses to discuss this at all. Make of that what you will.
- Retr0id - 10744 sekunder sedanHoly crap. This is like a software-reachable version of the dynamic memory aliasing hardware attack demonstrated by https://batteringram.eu/
- hn4jkltkab - 4588 sekunder sedan[dead]
- cumshitpiss - 7090 sekunder sedan[dead]
- decafbad - 9291 sekunder sedan[flagged]
- FabHK - 8071 sekunder sedanCould someone ELI5 please? Context, achievement, scope, consequences?
- - 7971 sekunder sedan
- Permik - 3402 sekunder sedanSkitter creek bath salts... Or SCBS Guess there'll be a talk called Secure Computing BullShit in the next Blackhat conf! I'll be eagerly waiting for it! :)
Nördnytt! 🤓